Security
InOrOut holds your team’s roster, schedule and conversations. This page explains how we keep that data safe.
How We Protect Your Account
- Passwords hashed with bcrypt — never stored in plain text
- All data encrypted in transit with TLS, with certificate-verified database connections
- JWT-based authentication with short-lived tokens
- Refresh tokens rotate on every use and are tracked per session, so signing out revokes that device immediately and a replayed token shuts down every session on the account
- Firebase App Check (Play Integrity / DeviceCheck) checks that requests come from a genuine, untampered build of the app; we monitor the results today and will refuse failing requests once enforcement is switched on
- QR sign-in requires a two-digit code that is shown only on the device asking to get in, so scanning alone can never authorize a session
- Sign-in routes are rate limited, and repeated failures lock the account for 15 minutes
- Strict HTTP security headers and request size limits on the server
- Secure token storage on device (Keychain / Keystore)
- An optional App lock (fingerprint, face or PIN) in the app, with a five-attempt limit before the device is signed out
- Every change is scanned automatically for vulnerable dependencies, leaked secrets and code security issues before it ships
- GDPR-compliant data handling with full export and deletion
Hosting & Infrastructure
Our servers are located in Europe (Frankfurt, Germany). We use managed PostgreSQL databases with automated backups and monitoring.
For what data we collect, who we share it with, and how long we keep it, see the Privacy Policy.
Last updated